Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GO-2026-6560
  • Go/github.com/hatchet-dev/hatchet
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter in github.com/hatchet-dev/hatchet 01 Oct
  • Fix available
GO-2026-6561
  • Go/github.com/hatchet-dev/hatchet
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher in github.com/hatchet-dev/hatchet 01 Oct
  • Fix available
GO-2026-6565
  • Go/github.com/hatchet-dev/hatchet
SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler in... 01 Oct
  • Fix available
GO-2026-6567
  • Go/github.com/hatchet-dev/hatchet
Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check in github.com/hatchet-dev/hatchet 01 Oct
  • Fix available
GO-2026-6535
  • Go/github.com/hatchet-dev/hatchet
Unauthenticated OAuth state CSRF via empty-state collision in... 28 Sep
  • Fix available
GHSA-992g-9cr3-vm5x
  • Go/github.com/hatchet-dev/hatchet
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter 22 Sep
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-9q4h-f4x5-ffq8
  • Go/github.com/hatchet-dev/hatchet
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher 22 Sep
  • Fix available
  • Severity - 3.1 (Low)
GHSA-g26x-m427-f48f
  • Go/github.com/hatchet-dev/hatchet
Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check 22 Sep
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-fjwv-jf2v-j499
  • Go/hatchet-dev/hatchet
Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler 22 Sep
  • Fix available
  • Severity - 4.1 (Medium)
CVE-2026-88978
  • github.com/hatchet-dev/hatchet
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter 21 Sep
  • Fix available
  • Severity - 4.3 (Medium)
CVE-2026-84298
  • github.com/hatchet-dev/hatchet
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher 21 Sep
  • Fix available
  • Severity - 3.1 (Low)
GHSA-phg3-3g28-wq9v
  • Go/hatchet
Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState 21 Sep
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-61687
  • github.com/hatchet-dev/hatchet
hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState 21 Sep
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-63342
  • github.com/hatchet-dev/hatchet
Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check 21 Sep
  • Fix available
  • Severity - 6.3 (Medium)
CVE-2026-61681
  • github.com/hatchet-dev/hatchet
Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler 21 Sep
  • Fix available
  • Severity - 4.1 (Medium)
GO-2026-6309
  • Go/github.com/hatchet-dev/hatchet
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe in github.com/hatchet-dev/hatchet 02 Sep
  • Fix available